Products: 2
    Vulnerabilities: 76
    Known Exploited: 0
    5
    Critical Level Threats
    29
    High Level Threats
    40
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-23697

    Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module

    Last Modified: Jul 14, 2026
    Published: Jul 07, 2026

    CVE-2026-23698

    Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload

    Last Modified: Jul 14, 2026
    Published: Jul 07, 2026

    CVE-2026-26460

    HTML Injection Vulnerability in Vtiger CRM Dashboard Module

    Last Modified: Apr 17, 2026
    Published: Apr 13, 2026

    CVE-2025-70936

    Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an authenticated user s session.

    Last Modified: Apr 17, 2026
    Published: Apr 13, 2026

    CVE-2025-45755

    A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user input, leading to persistent script execution.

    Last Modified: Jun 10, 2025
    Published: May 21, 2025
    Items Per Page
    Vtiger Vulnerabilities & Security CVEs | CVE-DB